Category Archives: DDoS Criminals

18 Election Websites Offline During the U.S. Midterm Elections possible DDoS attack

On the day of the U.S. midterm elections, the Contra Costa County Department of Elections website for was inaccessible starting at 7:20 a.m. local time. And it wasn’t alone, the Bay Area News Group reported that 18 election websites run by Florida-based SOE Software across the country were down for most of the election day. According to local news reports, Contra Costa County officials said the hosting of the website was contracted to SOE Software, which was also offline at the time. Election officials said SOE Software was working trying to fix the problem, and the sites were back online this week. The main function of election websites is to provide information on where voters can find polling stations, but they also provide features such as Vote by Mail ballot registration. Officials recommended that voters needing to find their polling station visit Get to the Polls, a website sponsored by the Pew Charitable Trust and others. It’s possible that the election websites were unprepared for the amount of traffic they would get on election day, but it’s also likely that a Distributed Denial of Service attack flooded SOE Software’s servers with requests, blocking legitimate traffic from reaching the websites it hosts. Source: http://www.thewhir.com/web-hosting-news/least-18-election-websites-offline-u-s-midterm-elections

Read More:
18 Election Websites Offline During the U.S. Midterm Elections possible DDoS attack

DDoS Explosion Imminent for Guy Fawkes Day

Guy Fawkes: famous for a plot to assassinate England’s King James in 1604 and for guarding copious amounts of gunpowder, is remembered every Nov. 5 in Britain with fireworks and bonfires. Researchers say that businesses should brace themselves for a different kind of plot: an influx of distributed denial of service (DDoS) attacks from hacktivist group Anonymous on Wednesday. “The forecast for the future looks dark, as we expect to see many DDoS attacks during Guy Fawkes Day on November 5, as the Anonymous collective has already announced various activities under the Operation Remember campaign,” said Candid Wueest, threat researcher at Symantec, in a blog. “However, hacktivists protesting for their ideological beliefs are not the only ones using DDoS attacks. We have also seen cases of extortion where targets have been financially blackmailed, as well as some targeted attacks using DDoS as a diversion to distract the local CERT team while the real attack was being carried out.” DDoS attacks have grown in intensity as well as in number in the last two years, although the duration of an attack is often down to just a few hours. Amplification attacks especially are very popular at the moment as they allow relatively small botnets to take out large targets with amplification factors of up to 500. For such an attack, spoofed traffic is sent to a third-party service, which will reflect the answer to the spoofed target. “Such attacks are simple to conduct for the attackers, but they can be devastating for the targeted companies,” said Wueest. From January to August 2014, Symantec has seen a 183% increase in DNS amplification attacks, making it the most popular method seen by Symantec’s Global Intelligence Network. Multiple methods are often used by attackers in order to make mitigation difficult and, to make matters worse, DDoS attack services can be hired for less than $10 on underground forums. “It is the distribution of hosts that attracts attackers — such as the group Anonymous — as it provides multiple advantages; undetectable location, multiple machines and identity anonymity,” said Alex Raistrick, director cybersecurity solutions at Palo Alto Networks. And all of that “which makes DDoS attacks an appealing instrument for destruction on Guy Fawkes Day,” he added. As far as mitigation, Raistrick noted that some attacks simply exploit vulnerabilities that subsequently crash or severely destabilize the system so that it can’t be accessed or used. “Segmentation helps to block attacks trying to spread from one area of the network to another,” he said. “Next-generation firewall will also directly contribute to a stronger overall security platform, starting with the endpoint and detecting attacks there as well as detecting when threats are attempting lateral moves within networks.” He added, “Essentially, make your estate difficult and expensive to breach — and the bad actors will go elsewhere.” Source: http://www.infosecurity-magazine.com/news/ddos-explosion-imminent-for-guy/

Follow this link:
DDoS Explosion Imminent for Guy Fawkes Day

#OpOrwahHammad – DDoS attack on Israeli Government Websites for Killing 14-Year-Old Orwah Hammad

Online hacktivist collective Anonymous has knocked 43 Israeli government websites offline in response to the killing of 14-year-old Palestinian-American boy Orwah Hammed by the Israeli Defense Forces (IDF). Conducted under the banner #OpOrwahHammad, the cyber-attacks knocked some of the main Israeli government websites offline using distributed denial of service (DDoS) attacks. Among the websites affected were those of the IDF, Office of the Prime Minister, Israel Ministry of Foreign Affairs, Israel Securities Authority , Ministry of Industry and Trade, State of Israel Mail and Israeli Immigration. Anonymous said in a statement published to coincide with the attacks: #?OpOrwahHammad has officially kicked-off now, and Israeli government websites are feeling it. Anonymous is targeting Israeli government websites in protest of the killing of young Orwah Hammad and many Palestinians alike. The world will not stand by such brutality. Israeli Government beware for you should have Expected Us. The hacktivist group also published a list of 43 websites it claims were knocked offline during the attack. At the time of writing, some of the websites on the list remain offline (such as the Ministry of Defence website) while others are back online (including the IDF website). Orwah Hammad The cyber-attacks were carried out in the name of Hammad, a 14-year-old boy who was shot in the head in the village of Silwad, north of Ramallah, on 24 October. The shooting of the Palestinian-American teenager led the US State Department to call for a “speedy and transparent investigation ” into the death. An Israeli army spokesman told Reuters Israeli forces “managed to prevent an attack when they encountered a Palestinian man hurling a molotov cocktail at them on the main road next to Silwad. They opened fire and they confirmed a hit”. The shooting happened during clashes in Arab areas in and around Jerusalem, in which several other people were injured. Source: http://www.ibtimes.co.uk/anonymous-shuts-down-israeli-government-websites-retaliation-killing-14-year-old-orwah-hammad-1471874

View article:
#OpOrwahHammad – DDoS attack on Israeli Government Websites for Killing 14-Year-Old Orwah Hammad

DDoS attack on Ukraine election commission website

Ukraine’s election commission website has been attacked by hackers on the eve of the country’s parliamentary polls. According to Ukrainian officials, the website came under cyber attack on Saturday, just one day before Ukraine is set to hold general elections. “There is a DDoS attack on the commission’s site,” said the Ukrainian government information security service. A distributed denial-of-service (DDoS) attack slows down or disables a website by flooding it with communications requests. The security service labeled the attack as “predictable” and went on to say that the website’s design insures that it could not be completely taken down and that it is currently completely functional. “If a site runs slowly, that doesn’t mean it has been destroyed by hackers,” the statement added. As for reports that the site was in control of hackers, Markiyan Lubkivskyy, an adviser to the Ukrainian Security Service said, “Any statements regarding the alleged successful unauthorized intrusions into the cyber space of the Central Election Commission or the elements of the elections systems do not correspond to the facts. Hackers are controlling nothing.” Ukraine’s snap elections were called in August as President Petro Poroshenko came under pressure to purge the parliament of lawmakers allegedly tied to the overthrown government of Viktor Yanukovych. As many as 36 million Ukrainians are eligible to take part in the parliamentary elections. The leaders of the breakaway eastern regions of Donetsk and Lugansk have refused to allow the polls to be held in territories under their control, with a population of almost three million. Ukraine’s mainly Russian-speaking regions in the east have been the scene of deadly clashes between pro-Russia protesters and the Ukrainian army since the government in Kiev launched military operations in mid-April in a bid to crush the protests.   Source: http://www.presstv.ir/detail/2014/10/25/383623/ukraines-election-website-hacked/

Read More:
DDoS attack on Ukraine election commission website

India accounts for 26% of top DDoS traffic

Majority of DDoS traffic in 2014 originated from India, says a new research from Symantec. Of the top 50 countries that witnessed the highest volume of originating DDoS traffic, India accounted for 26 percent of all DDoS traffic, followed by the USA with 17 percent, the research said. The results prove India has a high number of bot infected machines and a low adoption rate of filtering of spoofed packets, but may not imply that people behind the attacks are located in India because DDoS attacks are often orchestrated remotely. However, the study indicates that India is emerging as a hotbed to launch these attacks, potentially because of the low cyber security awareness, lack of adequate security practices and infrastructure, said Tarun Kaura, director, Technology Sales at Symantec India. The year 2014 saw an increase in the compromise of Linux servers, including those from cloud providers. These high bandwidth servers are then used as part of a botnet to perform DDoS attacks. The so-called “Booter” services can be hired for as little as INR 300 ($5 USD) to perform DDoS attacks for a few minutes against any target. Longer attacks can be bought for larger prices. They also offer monthly subscription services, often used by gamers to take down competitors. As the most attacked sector globally, the gaming industry experiences nearly 46 percent of attacks, followed by the software and media sectors While it’s not happening on a broad scale now, it’s likely we’ll see an increase in DDoS attacks originating from mobile and IoT devices in the future, Symantec said. DDoS attacks make an online service unavailable by overwhelming it with traffic from multiple sources. A Domain Name Server (DNS) amplification attack is a popular form of DDoS, which floods a publically available target system with DNS response traffic. Symantec’s research indicates that DNS amplification attacks have increased by 183 percent from January to August 2014. Motivations behind DDoS Attacks include hacking and financial blackmail with the threat of taking the business offline personal grudge. It also acts as a diversion technique to distract IT security response teams while a targeted attack is conducted. Source: http://www.infotechlead.com/2014/10/24/india-accounts-26-top-ddos-traffic-symantec-26196  

Originally posted here:
India accounts for 26% of top DDoS traffic

More than 70 Hong Kong government websites ‘under DDoS attack from Anonymous hackers’

Over 70 government websites have been targeted this month by cyberattacks believed to have been directed by hackers operating under the banner of Anonymous, a brand adopted by activists and hackers around the world. Commerce secretary Greg So Kam-leung told lawmakers that no information had been stolen or altered from the official websites, which had been intermittently inaccessible after surges of requests to access them. By Wednesday, eight men and three women had been arrested by police in connection with the cyberattacks, on suspicion of accessing a computer with criminal or dishonest intent, So said. “Attacks launched by the hacker group partly originated from Hong Kong, and partly from other regions outside Hong Kong,” he said. “Since the group can be joined by any netizen, [the attack] could be originated from all over the world and it is hard to find out their nationalities.” Internet users identifying themselves as Anonymous hackers issued a warning to the government and police force on October 2 after tear gas was fired at pro-democracy demonstrators in the city. A number of official sites were made inaccessible on October 3 by distributed denial-of-service (DDoS) attacks. During such attacks, website infrastructure is overwhelmed by a huge number of requests to access the site, ultimately making the site inaccessible. The attacks can also slow down website functionality. But So said the cyberattacks had not impacted significantly on the government’s online services, and emphasised that security had not been compromised. The website of the pro-democracy newspaper Apple Daily has also been the target of sustained cyberattacks in recent weeks, coinciding with a blockade of its offices in Tseung Kwan O by pro-Beijing protesters. No group has claimed responsibility for those cyberattacks, which followed similar attempts to make the Apple Daily website inaccessible in June during the Occupy Central electoral reform referendum. An attempt to block access to the referendum’s online polling system was described by one internet security expert as “the most sophisticated ever”. So mentioned that some individual local websites had also come under attack, but such actions had not had a “significant impact on the city’s economic activities”. Police are still investigating those cases, he said. Source: http://www.scmp.com/news/hong-kong/article/1622171/more-70-hong-kong-government-websites-under-attack-anonymous-hackers

Taken from:
More than 70 Hong Kong government websites ‘under DDoS attack from Anonymous hackers’

International Middle East Media Center back on-line after DDoS Attack

The website of the International Middle East Media Center (IMEMC) is back online after the Palestinian news service, under the auspices of the Palestinian Centre for Rapprochement between People, was forced off-line by a DoS attack and apparently let down by Hosting provider Bluehost. IMEMC and other new media came under increased attack during the Gaza war, while mainstream media were bleeding viewers, listeners and readers to new, alternative and independent news services. A several hundred percent increase in readers of news about the Gaza war may, ultimately, have prompted the UK parliament’s recognition of Palestine. The IMEMC website is under constant attack of one sort or the other, but these attacks increased significantly since the Gaza war, said the editor-in-chief Saed Bannoura to nsnbc. IMEMC’s website ultimately succumbed to a DoS attack on October 14, after the end of armed hostilities, but against the backdrop of the Swedish recognition of Palestine and the UK parliament’s yes vote to the recognition of Palestine on October 13. IMEMC, nsnbc, and a number of other new, independent or alternative media experienced a marked increase for the Palestine – Israel discourse. While nsnbc only registered a minor increase in daily readers, it noticed a marked increase in the number of read articles pertaining Palestine, Israel, and the related international discourse. IMEMC, which specifically covers Palestine and the Palestinian – Israeli discourse, experienced a significant increase in its number of readers and read articles. Saed Bannoura noted that IMEMC also experienced an increased interest in IMEMC’s Facebook page and Twitter account, adding, however, that there was a particular increase in interest for the IMEMC website. Bannoura said: “Our readership increased from two million hits per month to ten million hits per month … We have seen more and more reprints of our articles, and also, Abby Martin of Russia Today, was repeatedly quoting the IMEMC website, our statistics and our reports in her TV coverage” Saed Bannoura noted that IMEMC and other independent media often have people on the ground where major mainstream media are merely repeating the reports from establishment news agencies. It is noteworthy that the IMEMC website succumbed to the DoS attack on October 14, one day after the UK Parliament voted in favor of the recognition of Palestine and only two days after nsnbc published an article that documented an unprecedented level of harassment of alternative media, including IMEMC, nsnbc, Voltairenet, New Eastern Outlook, Land Destroyer Report, Infowars, Drudge Report and others. Mainstream media like the BBC, CNN and other were increasingly forced to adjust their coverage. This ”adjustment” and the flight away from the mainstream to alternatives is likely to have been a significant contributing factor to the landslide in public opinion in the UK, that led to the recognition of Palestine by the UK parliament. Speaking about the decades-long vilification of Palestinians and the misrepresentation of the Palestinian – Israeli discourse in Blockbuster Hollywood movies and mainstream media, Saed Bannoura said: “Well, it’s an unfortunate reality that most of the international media agencies are largely corporate owned and line-up with corporate lobbies. Therefore their coverage is poor to none, regarding Palestine issues, especially when it comes to Palestinian rights”. Another aspect of the involvement of strong corporate and government interest in media coverage is that alternative, internet-based media, are dependent on Hosting providers who often are in direct or indirect corporate relationship with, or dependent on business with major corporations which are known for their cooperation with intelligence agencies. One example is the well-documented cooperation between Google, Microsoft, Apple, and the U.S.’ National Security Agency. IMEMC’s now previous Hosting service, Bluehost, said Saed Bannoura, let IMEMC down when it was subjected to the DoS attack instead of providing any actionable help. Bannoura stressed, “that is their job, that is what we are paying them for”. It is noteworthy that Bluehost has a partnership with SiteLock, which also was involved in a harassment case pertaining nsnbc and others. October 18, nsnbc attempted to contact Bluehost via chat and phone. A sustained attempt to acquire the contact details of a media spokesperson or anyone who could speak on behalf of Bluehost failed. Also repeated direct calls to its violation of terms of service department were consistently answered by an answering machine, saying, “I’m sorry, that’s not a valid extension. Thank you for calling”. IMEMC has migrated the website to another hosting provider for now. Editor-in-chief Saed Bannoura agrees that alternative, new, and independent media could and maybe ought to form some kind of alliance with regard to negotiating with safe and ethical hosting service providers. The IMEMC website is on-line again, but the new media are likely to remain vulnerable as long as they don’t stand united against censorship and harassment. Source: http://www.imemc.org/article/69429

Visit link:
International Middle East Media Center back on-line after DDoS Attack

4 million UPnP devices may be vulnerable to attack

Akamai has observed the use of a new reflection and amplification DDoS attack that deliberately misuses communications protocols that come enabled on millions of home and office devices, including rou…

Continued here:
4 million UPnP devices may be vulnerable to attack

InSerbia News under DDoS attack from Serbia

Internet portal InSerbia News was unavailable on Saturday for a few hours due to a DDoS attack. The attack was committed from IP addresses in the range that belongs to internet providers in Serbia, which says that the attack was not performed using “infected” computers (botnet) throughout the world, but that it was organized and maybe coordinated attack for which were used only computers from Serbia. InSerbia wrote on October 7th about “Valter” program, which could also have been used for an attack on InSerbia portal. The way the network of people who use “Valter” is organized, and all of them are from Serbia, increases suspicion that the same software was used against us this time. Because of the situation we are forced to block all IP addresses from Serbia, so visitors from this country must pass “Captcha” check before they enter the website. We apologize to our readers because of this measure. After blocking access to IP addresses from Serbia, the server continued to function normally. At the moment this article is being written (4pm CEST), the attack is still in progress. Source: http://inserbia.info/today/2014/10/inserbia-news-under-ddos-attack-from-serbia/

Read the article:
InSerbia News under DDoS attack from Serbia

DDoS Attacks Can Take Down Your Online Services Part 3: Defending Against DDoS Attacks

Various defense strategies can be invoked to defend against DDoS attacks. Many of these depend upon the intensity of the attack. We discuss some of these in this article. Mitigation Strategies Some protection from DDoS attacks can be provided by firewalls and intrusion-prevention systems (systems that monitor for malicious activity). When a DDoS attack begins, it is important to determine the method or methods that the attacker is using. The web site’s front-end networking devices and the server’s processing flow may be able to be reconfigured to stop the attack. UDP Attacks UDP (User Datagram Protocol) attacks send a mass of UDP requests to a victim system, which must respond to each request. One example is a ping attack. It is an enormous influx of ping requests from an attacker that requires the victim server to respond with ping responses. Another example of a UDP attack is when the Internet Control Message Protocol (ICMP) must be used by the server to return error messages. The messages may indicate that a requested service is unavailable or that a host or router cannot be reached. An attacker may send UDP messages to random ports on the victim server, and the server must respond with a “port unreachable” ICMP message. Mitigation Strategy In the case of a UDP attack, the firewall could be configured to reject all UDP messages. True, this would prevent legitimate use of UDP messages, such as pings sent by monitoring services to measure the uptimes and response times of the web site. However, to be shown as failed by a monitoring service is much better than actually being down. SYN Attacks In a SYN attack, a mass of connection requests are sent to the victim server via SYN messages. Typically, the victim server will assign connection resources and will respond with SYN ACK messages. The server expects the requesting client to complete the connections with ACK messages. However, the attacker never completes the connections; and the server soon runs out of resources to handle further connection requests. Mitigation Strategy In this case, the server connection facility could be reconfigured so that it did not assign connection resources until it received the ACK from the client. This would slightly extend the time required to establish a connection but would protect the server from being overwhelmed by this sort of an attack. DNS Reflection Attack A DNS reflection attack allows an attacker to send a massive amount of malicious traffic to a victim server by generating a relatively small amount of traffic. DNS requests with a spoofed victim address are sent to multiple DNS systems to resolve a URL. The DNS servers respond to the victim system with DNS responses. What makes this sort of attack so efficient is that the DNS response is about 100 times as large as the DNS request. Therefore, the attacker only needs to generate 1% of the traffic that will be sent to the victim system. DNS reflection attacks depend upon DNS open resolvers that will accept requests from anywhere on the Internet. DNS open resolvers were supposed to have been removed from the Internet, but 27 million still remain. Mitigation Strategy A defense against DNS reflection attacks is to allow only DNS responses from the domain of the victim server to be passed to the server. Mitigation Services Given a sufficiently large DDoSattack, even the steps mentioned here may not protect a system. If nothing else, the attack can overwhelm the bandwidth of the victim’s connection to the Internet. In such cases, the next step is to use the services of a DDoS mitigation company with large data centers that can spread the attack volume over multiple data centers and can scrub the traffic to separate bad traffic from legitimate traffic. Prolexic, Tata Communications, AT&T, Verisign, CloudFare, and others are examples of DDoS mitigation providers. These services will also monitor the nature of the attack and will adjust their defenses to be effective in the face of an attacker that modifies its strategies as the attack progresses. Legality DDoS attacks are specifically outlawed by many countries. Violators in the U.K. can serve up to ten years in prison. The U.S. has similar penalties, as do most major countries. However, there are many countries from which DDoS attacks can be launched without penalty. With respect to the Spamhaus attack described in Part 1, the CEO of CyberBunker, a Dutch company, was arrested in Spain and was returned to the Netherlands for prosecution. Summary Companies must prepare for the likelihood of losing their public-facing web services and must make plans for how they will continue in operation if these services are taken down. This should be a major topic in their Business Continuity Plans. For instance, in the case of the bank attacks described in Part 1, many banks made plans to significantly increase their call center capabilities to handle customer services should their web sites be taken down by a DDoS attack. DDoS attacks are here to stay. They are motivated by too many factors – retaliation, political statements, aggressive competitors, ransom – and are fairly easy to launch. Botnets can be rented inexpensively. There are even sophisticated tools available on the darknet to launch significant attacks. The defenses against DDoS attacks are at best limited. The ultimate defense is to subscribe to a DDoS mitigation service that can be called upon when needed. Source: http://www.techproessentials.com/ddos-attacks-can-take-down-your-online-services-part-3-defending-against-ddos-attacks/

Read the article:
DDoS Attacks Can Take Down Your Online Services Part 3: Defending Against DDoS Attacks